Re: [pgadmin-support] pgadmin security issue

2008-04-23 Thread Dave Page
On Wed, Apr 23, 2008 at 8:11 AM, Julius Tuskenis <[EMAIL PROTECTED]> wrote: > Hi, Suren, > > > > > > /Even though we can restrict a user for couple of databases , the user can > disconnect from the current session and edit the connection properties/ > > > > /SO this means he could remove the /DB r

Re: [pgadmin-support] pgadmin security issue

2008-04-23 Thread Julius Tuskenis
Hi, Suren, // */PROBLEM 1/* /Even though we can restrict a user for couple of databases , the user can disconnect from the current session and edit the connection properties/ /SO this means he could remove the /DB restriction field/ “ datname IN ('live_db', 'test_db') “ and reconnect an

[pgadmin-support] pgadmin security issue

2008-04-22 Thread Suren Manatunga
Hi, (pgadmin 1.8.2 ) PROBLEM 1 Even though we can restrict a user for couple of databases , the user can disconnect from the current session and edit the connection properties SO this means he could remove the DB restriction field " datname IN ('live_db', 'test_db') " and reconnect and see al